Blog
-

•
CSP-AB FedRAMP Day Recap – Part 2
Part 2: The Hard Part May Be What Comes Next The CSP side of FedRAMP 20x is moving quickly. What I heard…
-

•
CSP-AB FedRAMP Day Recap
Part 1: 20x – What Actually Changes Last week I participated in the CSP-AB Summit and I spent a lot of FedRAMP…
-

•
Decoding RFC 2119: The Weight of “SHOULD” in FedRAMP 20x
Decoding RFC 2119: The Weight of “SHOULD” in FedRAMP 20x There is a specific moment, if you spend enough time reading FedRAMP…
-

•
FedRAMP 20x & CR26: Moving from Paperwork to Continuous Assurance
Series: Modernizing Federal Cloud Compliance Part 2: FedRAMP 20x & CR26: Moving from Paperwork to Continuous Assurance In Part 1, we looked…
-

•
The New Era of FedRAMP: How OMB M-24-15 Redefined Cloud Security
Series: Modernizing Federal Cloud Compliance Part 1: The New Era of FedRAMP: How OMB M-24-15 Redefined Cloud Security For more than a…
-

•
Level 1 vs. Level 2: Which CMMC Tier Do You Actually Need?
For Department of Defense (DoD) contractors, the Cybersecurity Maturity Model Certification (CMMC) 2.0 is no longer a distant requirement. It is a…
-

•
CMMC 101: What Is It and Why Does Your Contract Depend on It?
For years, the Department of Defense (DoD) operated on a “trust but verify” model: though, in practice, there was a lot more…
-

•
CMMC Phase II Paused: What the DoD’s 60-Day Review Means for Defense Contractors
On July 13, 2026, the Department of Defense (DoD) issued a series of memoranda that introduced a significant pivot for the Cybersecurity…
